CVE Vulnerabilities

CVE-2020-18898

Uncontrolled Recursion

Published: Aug 19, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

NameVendorStart VersionEnd Version
Exiv2Exiv20.27 (including)0.27 (including)
Red Hat Enterprise Linux 8RedHatcompat-exiv2-026-0:0.26-7.el8*
Red Hat Enterprise Linux 8RedHatexiv2-0:0.27.5-2.el8*
Exiv2Ubuntubionic*
Exiv2Ubuntuhirsute*
Exiv2Ubuntuimpish*
Exiv2Ubuntukinetic*
Exiv2Ubuntutrusty*
Exiv2Ubuntuxenial*

Potential Mitigations

References